[Congressional Bills 119th Congress]
[From the U.S. Government Publishing Office]
[S. 5061 Introduced in Senate (IS)]

<DOC>






119th CONGRESS
  2d Session
                                S. 5061

To improve the tracking and processing of security and safety incidents 
   and risks associated with artificial intelligence, and for other 
                               purposes.


_______________________________________________________________________


                   IN THE SENATE OF THE UNITED STATES

                             July 21, 2026

  Mr. Warner introduced the following bill; which was read twice and 
   referred to the Committee on Commerce, Science, and Transportation

_______________________________________________________________________

                                 A BILL


 
To improve the tracking and processing of security and safety incidents 
   and risks associated with artificial intelligence, and for other 
                               purposes.

    Be it enacted by the Senate and House of Representatives of the 
United States of America in Congress assembled,

SECTION 1. SHORT TITLE.

    This Act may be cited as the ``Secure Artificial Intelligence 
Development Act of 2026'' or the ``Secure A.I. Development Act of 
2026''.

SEC. 2. DEFINITIONS.

    In this Act:
            (1) Adversarial-artificial intelligence.--The term 
        ``adversarial-artificial intelligence'' means techniques or 
        procedures to extract information about the behavior or 
        characteristics of an artificial intelligence system, or to 
        learn how to manipulate an artificial intelligence system, in 
        order to subvert the confidentiality, integrity, or 
        availability of an artificial intelligence system or adjacent 
        system.
            (2) Artificial intelligence.--The term ``artificial 
        intelligence'' has the meaning given the term in section 5002 
        of the National Artificial Intelligence Initiative Act of 2020 
        (15 U.S.C. 9401).
            (3) Artificial intelligence safety incident.--The term 
        ``artificial intelligence safety incident'' means an event that 
        materially increases the risk that operation of an artificial 
        intelligence system leads to a state in which human life, 
        health, property, or the environment is endangered.
            (4) Artificial intelligence security incident.--The term 
        ``artificial intelligence security incident'' means an event 
        that materially increases--
                    (A) the risk that operation of an artificial 
                intelligence system occurs in a way that enables the 
                unauthorized extraction of information about the 
                behavior or characteristics of an artificial 
                intelligence system by an unauthorized party; or
                    (B) the ability to manipulate an artificial 
                intelligence system in order to subvert the 
                confidentiality, integrity, or availability of an 
                artificial intelligence system or adjacent system.
            (5) Artificial intelligence security vulnerability.--The 
        term ``artificial intelligence security vulnerability'' means a 
        weakness in an artificial intelligence system that could be 
        exploited by a third party to subvert, without authorization, 
        the confidentiality, integrity, or availability of an 
        artificial intelligence system, including through techniques 
        such as--
                    (A) data poisoning;
                    (B) evasion attacks;
                    (C) privacy-based attacks;
                    (D) model theft or extraction attacks;
                    (E) attacks designed to circumvent or degrade the 
                safety, alignment, or access control mechanisms of an 
                artificial intelligence system; and
                    (F) adversarial machine learning attacks as 
                described in National Institute of Standards and 
                Technology Trustworthy and Responsible Artificial 
                Intelligence 100-2e2025 (relating to Adversarial 
                Machine Learning), or successor publication.

SEC. 3. ENABLING TESTING OF FRONTIER ARTIFICIAL INTELLIGENCE MODELS 
              PRIOR TO PUBLIC RELEASE.

    (a) Definitions.--In this section:
            (1) Board.--The term ``Board'' means the Artificial 
        Intelligence Risk Board established under subsection (b)(1).
            (2) Critical infrastructure.--The term ``critical 
        infrastructure'' has the meaning provided in section 1016(e) of 
        the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)).
            (3) Frontier artificial intelligence model.--The term 
        ``frontier artificial intelligence model'' means an artificial 
        intelligence model, or system combining multiple artificial 
        intelligence models, that exhibits or could be modified to 
        exhibit high levels of performance at tasks that pose a serious 
        risk to national security, national economic security, or 
        public health or safety.
            (4) Institute.--The term ``Institute'' means the National 
        Institute of Standards and Technology.
            (5) Secretary.--The term ``Secretary'' means the Secretary 
        of Commerce.
    (b) The Artificial Intelligence Risk Board.--
            (1) Establishment.--
                    (A) In general.--Not later than 90 days after the 
                date of the enactment of this Act, the Secretary shall 
                establish within the Institute a board to address 
                artificial intelligence risks.
                    (B) Designation.--The board established under 
                subparagraph (A) shall be known as the ``Artificial 
                Intelligence Risk Board''.
            (2) Membership.--
                    (A) Composition.--The Board shall be composed of 
                members who are appointed as follows:
                            (i) One or more members selected by the 
                        Director of the National Institute of 
                        Standards.
                            (ii) One or more members selected by the 
                        Secretary.
                            (iii) One or more members selected by the 
                        Director of the Cybersecurity and 
                        Infrastructure Security Agency.
                            (iv) One or more members selected by the 
                        Director of the National Security Agency.
                            (v) One or more members selected by the 
                        Secretary of the Treasury.
                    (B) Nongovernmental experts.--In addition to the 
                members of the Board appointed under subparagraph (A), 
                the Secretary shall appoint members who are not 
                officers or employees of the Federal Government and who 
                the Secretary selects from among individuals who--
                            (i) are leading technical experts not 
                        affiliated with a developer or provider of 
                        artificial intelligence systems;
                            (ii) are leading technical experts 
                        affiliated with developers or providers of 
                        artificial intelligence systems;
                            (iii) are individuals with expertise in 
                        developing evaluations to test artificial 
                        intelligence models; and
                            (iv) have knowledge or expertise that the 
                        Secretary determines would further the purpose 
                        of the duties of the Board.
            (3) Terms and vacancies.--
                    (A) Terms.--Each member of the Board shall serve 1 
                term of not longer than 3 years and may be reappointed 
                for 1 successive term of not longer than 3 years.
                    (B) Vacancy replacement.--The memebrs of the Board 
                shall develop a vacancy replacement procedure that 
                includes--
                            (i) for vacancies occurring due to the end 
                        of a member's term, a vote not later than 90 
                        days before the last day of the member's term; 
                        and
                            (ii) for vacancies occurring under 
                        subparagraph (C) or for any other reason, the 
                        chair of the Board shall nominate a replacement 
                        from the same stakeholder category under 
                        paragraph (2), to the extent practicable, as 
                        the member creating the vacancy, subject to 
                        approval by a majority vote of the members of 
                        the Board.
                    (C) Removal.--Any member who fails to comply with 
                the conflict of interest policy adopted pursuant to 
                paragraph (5)(D) shall be removed from the Board.
                    (D) Chair.--The chair of the Board shall be 
                selected by a majority vote among a quorum of the 
                members appointed under paragraph (2) and shall serve 
                not more than 1 two-year term.
            (4) Member access to classified information.--
                    (A) Access.--
                            (i) In general.--Not later than 60 days 
                        after the date on which a member is first 
                        appointed to the Board and before the member is 
                        granted access to any classified information 
                        necessary to participate in a closed session 
                        pursuant to paragraph (5)(F), the Secretary 
                        shall determine, for the purposes of the Board, 
                        if the member should be restricted from 
                        reviewing, discussing, or possessing classified 
                        information.
                            (ii) Management.--Access to classified 
                        information shall be managed in accordance with 
                        Executive Order 13526 (50 U.S.C. 3161 note; 
                        relating to classified national security 
                        information), or any subsequent corresponding 
                        Executive order.
                            (iii) Clearance requirement.--The Secretary 
                        shall sponsor each member of the Board for a 
                        security clearance at the Top Secret level with 
                        access to sensitive compartmented information, 
                        as appropriate, for the purposes of 
                        participating in carrying out the duties of the 
                        Board.
                            (iv) Clearance requirement.--Each member of 
                        the Board shall obtain a security clearance 
                        unless denied by the appropriate authorities or 
                        if the Secretary determines a member should be 
                        restricted from reviewing, discussing, or 
                        possessing classified information. In either 
                        instance, such member shall be removed from the 
                        Board and a new member shall be appointed 
                        pursuant to the vacancy procedures under 
                        paragraph (3)(B) to replace such removed 
                        member.
                    (B) Protection of information.--A member of the 
                Board granted access to classified information shall 
                protect the classified information in accordance with 
                the applicable requirements for the particular level of 
                classification of the information.
                    (C) Rule of construction.--Nothing in this 
                paragraph shall be construed to affect the existing 
                security clearance of a member of the Board or the 
                authority of a Federal agency to provide or deny a 
                member of the Board access to any specific pieces of 
                classified information.
            (5) Procedures.--
                    (A) Designated federal officer.--The Secretary 
                shall designate a Federal officer or employee to serve 
                as the designated Federal officer of the Board, 
                consistent with the requirements of chapter 10 of title 
                5, United States Code (common known as the ``Federal 
                Advisory Committee Act'').
                    (B) Initial meeting and bylaws.--Not later than 120 
                days after the date of the enactment of this Act, the 
                Board shall convene and establish bylaws that--
                            (i) govern quorum and voting rules, 
                        including implementation of the decisionmaking 
                        majority voting requirement specified in 
                        paragraph (5)(C)(ii); and
                            (ii) set deliverable timelines and meeting 
                        schedules.
                    (C) Operating procedures.--Unless otherwise 
                specified, the Board shall adopt written procedures 
                governing its meetings, consistent with chapter 10 of 
                title 5, United States Code, that include--
                            (i) requirements for public notice of 
                        meetings and the maintenance of records and 
                        minutes;
                            (ii) decision making by majority vote of 
                        those present and voting;
                            (iii) authorization for the establishment 
                        of subgroups as necessary, subject to the 
                        approval of the chair of the Board; and
                            (iv) approval of the meeting agendas by the 
                        chair in consultation with the designated 
                        Federal officer under subparagraph (A) to 
                        ensure compliance with applicable laws.
                    (D) Conflict-of-interest policy.--
                            (i) In general.--The Board shall adopt and 
                        enforce a written conflict of interest policy 
                        to ensure that members of the Board have a 
                        fiduciary responsibility to the Board, a duty 
                        to report conflicts of interest, including the 
                        appearance of a conflict of interest, and do 
                        not participate in deliberations or votes from 
                        which they personally or their employer would 
                        directly and materially benefit.
                            (ii) Required disclosures.--The policy 
                        under clause (i) shall require each member to 
                        publicly disclose all relevant financial and 
                        employment relationships and include recusal 
                        procedures in the event of a conflict.
                            (iii) Records.--The designated Federal 
                        officer under subparagraph (A) shall maintain 
                        records of disclosures under clause (ii) of 
                        this subparagraph and make summaries of the 
                        disclosures available to the Secretary.
                    (E) Threat information access.--The Director of 
                National Intelligence, in coordination with the heads 
                of other appropriate Federal entities, shall ensure 
                that the Board has access to relevant cybersecurity 
                threat information, including through closed or 
                classified briefings or the provision of classified 
                information, when appropriate.
                    (F) Closed sessions.--Notwithstanding section 1009 
                of title 5, United States Code, the Board may hold 
                closed or restricted-access sessions when the Secretary 
                determines that the matters to be discussed involve any 
                of the following:
                            (i) Classified information.
                            (ii) Sensitive cybersecurity 
                        vulnerabilities.
                            (iii) Threat information.
                            (iv) Proprietary business information.
                            (v) Other information exempt from public 
                        disclosure under section 552 of title 5, United 
                        States Code.
            (6) Duties.--
                    (A) In general.--The Board shall--
                            (i) develop a process to perform technical 
                        evaluations to determine what capabilities or 
                        combination of capabilities constitute high 
                        levels of performance at tasks that pose a 
                        serious risk to national security, national 
                        economic security, or public health or safety; 
                        and
                            (ii) develop best practices, including--
                                    (I) standardize formats and 
                                processes for publishing model cards 
                                with technical details of artificial 
                                intelligence systems;
                                    (II) recommendations for 
                                maintaining cybersecurity measures for 
                                developers or providers of artificial 
                                intelligence systems;
                                    (III) processes and metrics for 
                                developers or providers of artificial 
                                intelligence systems to use to evaluate 
                                risks from employees or other personnel 
                                who have access to artificial 
                                intelligence systems developed or in 
                                development by developers or providers 
                                of artificial intelligence systems; and
                                    (IV) recommendations on appropriate 
                                financial and other resourcing for 
                                developers or providers of artificial 
                                intelligence systems to robustly engage 
                                in safety and security research focused 
                                on the deployment of frontier 
                                artificial intelligence models.
                    (B) Periodic reassessment of technical evaluations 
                and best practices.--The Board shall periodically 
                reassess the technical evaluations and best practices 
                the Board develops under this subsection.
    (c) Requirement That Providers of Frontier Artificial Intelligence 
Models Give Access to National Security Agency Before Public Release.--
Not later than 21 calendar days before a provider introduces into 
interstate or foreign commerce a frontier artificial intelligence 
model, the provider shall make available to the Artificial Intelligence 
Security Center, established by the Director of the National Security 
Agency under section 6504 of the Intelligence Authorization Act for 
Fiscal Year 2025 (division F of Public Law 118-159; 50 U.S.C. 3602 
note), access to the frontier artificial intelligence model, including 
model's weights, configuration files, runtimes, or software libraries 
necessary to operate the frontier artificial intelligence model.
    (d) Frontier Artificial Intelligence Model Registry.--
            (1) Establishment of registry.--Not later than 90 days 
        after the date of the enactment of this Act, the Director of 
        the National Institute of Standards and Technology shall 
        establish a registry of frontier models that are available to 
        the public.
            (2) Rules and procedures.--In establishing the registry 
        under paragraph (1), the Director of the National Institute of 
        Standards and Technology shall establish rules and procedures 
        for--
                    (A) a provider of a frontier artificial 
                intelligence model to register the frontier artificial 
                intelligence model;
                    (B) a provider of a frontier artificial 
                intelligence model to contest the need for registering 
                the frontier artificial intelligence model;
                    (C) removing a frontier artificial intelligence 
                model from the registry;
                    (D) a provider of a frontier artificial 
                intelligence model to attest that the provider 
                submitted the frontier artificial intelligence model to 
                the test-bed established under section 6504(e) of the 
                Intelligence Authorization Act for Fiscal Year 2025 
                (division F of Public Law 118-159; 50 U.S.C. 3602 
                note), as amended by subsection (e); and
                    (E) such other purposes the Director deems 
                necessary.
            (3) Obligation to register.--Each provider of a frontier 
        artificial intelligence model shall register that frontier 
        artificial intelligence model with the registry established 
        under paragraph (1) before introducing the frontier artificial 
        intelligence model into interstate or foreign commerce.
    (e) Enforcement; Ability To Cure.--
            (1) Referrals for enforcement.--In any case in which the 
        Director of the National Institute of Standards and Technology 
        determines that a frontier artificial intelligence model has 
        been introduced into interstate or foreign commerce by a 
        provider of the frontier artificial intelligence in violation 
        of subsection (c), the Director of the National Institute of 
        Standards and Technology shall notify the Attorney General.
            (2) Enforcement.--The Attorney General shall enforce this 
        section.
            (3) Penalty.--Whoever violates subsection (c) shall be 
        fined an amount equal to not less than $100,000 per day for 
        each day during which a frontier artificial intelligence model 
        controlled by that person is available through interstate and 
        foreign commerce without having obtained the voluntary security 
        guidance issued under section 6504(e)(3) of the Intelligence 
        Authorization Act for Fiscal Year 2025 (division F of Public 
        Law 118-159; 50 U.S.C. 3602 note), as amended by subsection 
        (f).
            (4) Right to cure.--
                    (A) Notification.--Prior to commending an 
                enforcement action against a provider of a frontier 
                artificial intelligence model for violating subsection 
                (c), the Attorney General shall notify the provider and 
                allow the provider 7 calendar days following the notice 
                of violation for the violator to come into compliance 
                pursuant to subparagraph (B).
                    (B) Process to cure.--In order for a provider of a 
                frontier artificial intelligence model to come into 
                compliance pursuant to this subparagraph, the provider 
                shall demonstrate to the Attorney General that the 
                provider has--
                            (i) withdrawn from interstate and foreign 
                        commerce the frontier artificial intelligence 
                        model that gave rise to the violation of 
                        subsection (c); and
                            (ii) given to the National Security Agency 
                        access to the frontier artificial intelligence 
                        model pursuant to subsection (c).
    (f) National Security Agency Research-Test-Bed.--Section 6504 of 
the Intelligence Authorization Act for Fiscal Year 2025 (division F of 
Public Law 118-159; 50 U.S.C. 3602 note) is amended--
            (1) in subsection (c)--
                    (A) by redesignating paragraph (4) as paragraph 
                (5); and
                    (B) by inserting after paragraph (3) the following 
                new paragraph (4):
            ``(3) Making available a research test-bed to private 
        sector, Federal and qualified independent expert participants, 
        on a subsidized basis, to engage in artificial intelligence 
        security research, including through the secure provision of 
        access in a secure environment for pre-deployment testing of 
        any frontier artificial intelligence model prior to public 
        release.'';
            (2) by redesignating subsection (e) as subsection (f); and
            (3) by inserting after subsection (d) the following:
    ``(e) Test-Bed Requirements.--
            ``(1) Access and terms of usage.--
                    ``(A) Outside participation.--The Director shall 
                establish a process by which critical infrastructure 
                operators, as well private sector entities that develop 
                or maintain information systems utilized by critical 
                infrastructure operators, shall access a secure test-
                bed for the purpose of testing and evaluating the 
                impact of frontier artificial intelligence models on 
                information systems maintained by critical 
                infrastructure operators prior to public release or 
                distribution of such models.
                    ``(B) Researcher access.--The Director shall 
                establish terms of usage governing access to the test-
                bed made available under subsection (c)(4), with 
                limitations on researcher publication to the extent 
                necessary to protect classified information or 
                proprietary information provided by private sector 
                participants.
                    ``(C) Availability to federal agencies.--The 
                Director shall ensure that the test-bed made available 
                under subsection (c)(4) is also made available to other 
                Federal agencies on a cost-recovery basis.
            ``(2) Use of certain infrastructure and other resources.--
        In carrying out subsection (c)(4), the Director shall leverage, 
        to the greatest extent practicable, infrastructure and other 
        resources provided under section 5.2 of Executive Order 14110 
        (88 Fed. Reg. 75191; relating to safe, secure, and trustworthy 
        development and use of artificial intelligence).
            ``(3) Voluntary security guidance.--The Director shall 
        share relevant guidance, informed by pre-deployment testing in 
        the secure test-bed environment identified in subsection (c), 
        to inform voluntary vendor actions to mitigate against 
        potential security threats to such models, or the ability of 
        foreign actors to utilize such models for computer network 
        exploitation campaigns against information systems utilized by 
        critical infrastructure operators, the design or development of 
        weapons systems, or to further foreign surveillance 
        capabilities.''.

SEC. 4. DATABASE FOR ARTIFICIAL INTELLIGENCE SECURITY AND SAFETY 
              INCIDENTS AND RISKS.

    (a) Voluntary Tracking of Artificial Intelligence Security and 
Artificial Intelligence Safety Incidents.--
            (1) Voluntary submissions.--Not later than 1 year after the 
        date of the enactment of this Act, the Director of the National 
        Institute of Standards and Technology shall, in coordination 
        with the Director of the Cybersecurity and Infrastructure 
        Security Agency, establish mechanisms by which private sector 
        entities, public sector organizations, civil society groups, 
        and academic researchers may voluntarily share information with 
        the National Institute of Standards and Technology on confirmed 
        or suspected artificial intelligence security or artificial 
        intelligence safety incidents, in a manner that preserves 
        confidentiality of any affected party, which shall--
                    (A) leverage, to the greatest extent possible, 
                standardized disclosure and incident description 
                formats;
                    (B) develop processes to associate reports 
                pertaining to the same incident with a single incident 
                identifier;
                    (C) establish classification, information 
                retrieval, and reporting mechanisms that sufficiently 
                differentiate between artificial intelligence security 
                incidents and artificial intelligence safety incidents; 
                and
                    (D) create appropriate taxonomies to classify 
                incidents based on relevant characteristics, impact, or 
                other relevant criteria.
            (2) Publicly accessible database.--
                    (A) Establishment of database required.--Not later 
                than 1 year after the date of the enactment of this 
                Act, the Director of the Institute shall, in 
                coordination with the Director of the Cybersecurity and 
                Infrastructure Security Agency, establish a publicly 
                accessible database of artificial intelligence security 
                incidents and artificial intelligence safety incidents.
                    (B) Review and population of database.--Upon 
                receipt of relevant information on an artificial 
                intelligence security or artificial intelligence safety 
                incident under paragraph (1), the Director of the 
                Institute shall review the information and determine 
                whether the described incident constitutes an 
                artificial intelligence security or artificial 
                intelligence safety risk appropriate for inclusion in 
                the database developed and established under 
                subparagraph (A).
                    (C) Identification of causal factors.--When making 
                a determination under subparagraph (B), the Director of 
                the Institute shall identify causal factors for the 
                artificial intelligence security incident or the 
                artificial intelligence safety incident, including--
                            (i) the artificial intelligence system;
                            (ii) the deployment of the artificial 
                        intelligence systems; and
                            (iii) practices related to the operation of 
                        the artificial intelligence system, including 
                        misuse of the artificial intelligence system.
                    (D) Priorities.--In evaluating information under 
                subparagraph (B) and determining under such 
                subparagraph whether to include a report of an incident 
                in the database required by subparagraph (A), the 
                Director shall prioritize inclusion in the database of 
                cases in which a described incident--
                            (i) describes an artificial intelligence 
                        system used in critical infrastructure or 
                        safety-critical systems;
                            (ii) would result in a high-severity or 
                        catastrophic impact to the people or economy of 
                        the United States; or
                            (iii) includes an artificial intelligence 
                        system widely used in commercial or public 
                        sector contexts in the United States.
            (3) Exemption from disclosure; reports and anonymity.--
                    (A) Anonymity.--The Director shall populate the 
                voluntary database developed and established under 
                paragraph (2)(A) with incidents based on public reports 
                and information shared using the mechanism established 
                pursuant to paragraph (1), ensuring that any incident 
                description sufficiently anonymizes those affected, 
                unless those who are affected have consented to their 
                names being included in the database.
                    (B) Exemption from disclosure.--Any information 
                shared using the mechanism established pursuant to 
                paragraph (1)--
                            (i) shall be exempt from disclosure and 
                        withheld, unless an affected party consents to 
                        the inclusion of their names in the database as 
                        provided for under subparagraph (A), from the 
                        public, pursuant to section 552(b)(3)(B) of 
                        title 5, United States Code, and any other 
                        provision of United States law or law of any 
                        State, political subdivision or agency thereof, 
                        or Tribe requiring disclosure of information or 
                        records; and
                            (ii) shall not be deemed a waiver of any 
                        applicable privilege or protection, including 
                        trade secret protection.
                    (C) Consultation required.--Before publishing 
                information regarding artificial intelligence safety 
                incident under paragraph (2)(B), the Director shall 
                consult with the developer or provider of the 
                artificial intelligence system involved in an incident.
    (b) Material Risk Guidance.--Not later than 180 days after the date 
of the enactment of this Act the Director of the National Institute of 
Standards and Technology shall, in coordination with the Director of 
the Cybersecurity and Infrastructure Security Agency, publish 
nonbinding guidance that provides illustrative criteria and examples 
for determining when an event ``materially increases'' a risk for 
purposes of paragraphs (3) and (4) of section 2.

SEC. 5. UPDATING PROCESSES AND PROCEDURES RELATING TO CYBERSECURITY 
              VULNERABILITIES.

    (a) Definitions.--In this section:
            (1) Common vulnerabilities and exposures program.--The term 
        ``Common Vulnerabilities and Exposures Program'' means the 
        reference guide and classification system for publicly known 
        information security vulnerabilities sponsored by the 
        Cybersecurity and Infrastructure Security Agency.
            (2) Relevant congressional committees.--The term ``relevant 
        congressional committees'' means--
                    (A) the Committee on Homeland Security and 
                Governmental Affairs, the Committee on Commerce, 
                Science, and Transportation, the Select Committee on 
                Intelligence, and the Committee on the Judiciary of the 
                Senate; and
                    (B) the Committee on Oversight and Government 
                Reform, the Committee on Energy and Commerce, the 
                Permanent Select Committee on Intelligence, and the 
                Committee on the Judiciary of the House of 
                Representatives.
    (b) Processes and Procedures for Vulnerability Management.--Not 
later than 180 days after the date of the enactment of this Act, the 
Director of the National Institute of Standards and Technology shall--
            (1) comprehensively evaluate, and develop a strategic plan 
        to reform, the structure and processes of the National 
        Vulnerability Database in light of significant increase in the 
        volume of vulnerabilities in information systems identified by 
        artificial intelligence systems, including recommendations and 
        guidance related to assisting in determining prioritization of 
        identified vulnerability patching and mitigation;
            (2) initiate a process to utilize advanced artificial 
        intelligence systems to characterize vulnerabilities as part of 
        the National Vulnerability Database;
            (3) initiate a process to update processes and procedures 
        associated with the National Vulnerability Database of the 
        Institute to ensure that the database and associated 
        vulnerability management processes incorporate artificial 
        intelligence security vulnerabilities to the greatest extent 
        practicable;
            (4) identify any characteristics of artificial intelligence 
        security vulnerabilities that make utilization of the National 
        Vulnerability Database inappropriate and develop processes and 
        procedures for vulnerability management for those 
        vulnerabilities; and
            (5) initiate a process to update the Secure Software 
        Development Framework set forth in National Institute of 
        Standards and Technology Special Publication 800-218 and 
        include guidance and best practices for using artificial 
        intelligence in code generation and security review.
    (c) Updates to Common Vulnerabilities and Exposures Program.--Not 
later than 180 days after the date of enactment of this Act, the 
Director of the Cybersecurity and Infrastructure Security Agency 
shall--
            (1) initiate a process to update processes and procedures 
        associated with the Common Vulnerabilities and Exposures 
        Program to ensure that the program and associated processes 
        identify and enumerate artificial intelligence security 
        vulnerabilities to the greatest extent practicable; and
            (2) identify any characteristic of artificial intelligence 
        security vulnerabilities that make utilization of the Common 
        Vulnerabilities and Exposures Program inappropriate and develop 
        processes and procedures for vulnerability identification and 
        enumeration for those artificial intelligence security 
        vulnerabilities.
    (d) Submission to Congress.--Upon completion of the processes 
required in subsections (a) and (b), the Director of the National 
Institute of Standards and Technology and the Director of the 
Cybersecurity and Infrastructure Security Agency, respectively, shall 
submit a strategic plan to Congress identifying courses of action under 
existing authorities, or identifying specific legislative amendments, 
necessary to address accelerating security risks associated with 
artificial intelligence systems.
    (e) Evaluation of Consensus Standards for Vulnerability 
Disclosure.--
            (1) In general.--Not later than 30 days after the date of 
        the enactment of this Act, the Director of the National 
        Institute of Standards and Technology shall, in coordination 
        with the Director of the Cybersecurity and Infrastructure 
        Security Agency, initiate a multi-stakeholder process to 
        evaluate whether existing voluntary consensus standards and 
        processes for vulnerability reporting processes associated with 
        the security of information systems effectively accommodate the 
        significant increased volume of vulnerabilities in information 
        systems identified by artificial intelligence systems, as well 
        as the unique nature of artificial intelligence security 
        vulnerabilities.
            (2) Report.--
                    (A) Submission.--Not later than 180 days after the 
                date on which the evaluation under paragraph (1) is 
                carried out, the Director shall submit a report to the 
                relevant congressional committees on the sufficiency of 
                existing vulnerability reporting processes and 
                standards to accommodate the significant increased 
                volume of vulnerabilities in information systems 
                identified by artificial intelligence systems, as well 
                as artificial intelligence security vulnerabilities.
                    (B) Post-report action.--If the Director concludes 
                in the report submitted under subparagraph (A) that 
                existing vulnerability reporting processes and 
                standards do not effectively accommodate the 
                significant increased volume of vulnerabilities in 
                information systems identified by artificial 
                intelligence systems, as well as the reporting of 
                artificial intelligence security vulnerabilities, the 
                Director shall initiate a process, in consultation with 
                the Director of the National Institute of Standards and 
                Technology and the Director of the Office of Management 
                and Budget, to update relevant vulnerability reporting 
                processes, including the Department of Homeland 
                Security Binding Operational Directive 20-01, or any 
                subsequent directive.

SEC. 6. REVIEW OF ARTIFICIAL INTELLIGENCE SECURITY VULNERABILITIES 
              UNDER VULNERABILITIES EQUITIES PROCESS.

    (a) Definitions.--In this section:
            (1) Appropriate congressional committees.--The term 
        ``appropriate congressional committees'' means--
                    (A) the Select Committee on Intelligence of the 
                Senate;
                    (B) the Committee on Homeland Security and 
                Governmental Affairs of the Senate;
                    (C) the Committee on the Judiciary of the Senate;
                    (D) the Committee on Armed Services of the Senate;
                    (E) the Permanent Select Committee on Intelligence 
                of the House of Representatives;
                    (F) the Committee on Homeland Security of the House 
                of Representatives;
                    (G) the Committee on the Judiciary of the House of 
                Representatives; and
                    (H) the Committee on Armed Services of the House of 
                Representatives.
            (2) Vulnerabilities equities policy and process document.--
        The term ``Vulnerabilities Equities Policy and Process 
        document'' means the executive branch document entitled 
        ``Vulnerabilities Equities Policy and Process for the United 
        States Government'' dated November 15, 2017.
            (3) Vulnerabilities equities process.--The term 
        ``Vulnerabilities Equities Process'' means the interagency 
        review of vulnerabilities carried out pursuant to the 
        Vulnerabilities Equities Policy and Process document or any 
        successor document.
    (b) Evaluation; Report.--Not later than 90 days after the date of 
the enactment of this Act, the Federal departments and agencies 
participating in the Vulnerabilities Equities Process shall--
            (1) evaluate whether the existing Vulnerabilities Equities 
        Process sufficiently accommodates the submission and review of 
        artificial intelligence security vulnerabilities; and
            (2) submit to the appropriate congressional committees a 
        report describing the applicability of the Vulnerabilities 
        Equities Process to such vulnerabilities, including whether the 
        submission and review of such vulnerabilities under the 
        Vulnerabilities Equities Process would result in an unduly 
        large volume of notifications to affected vendors and, if so, 
        an assessment of mechanisms to manage the volume of such 
        notifications.
    (c) Process.--In carrying out subsection (b), if the Federal 
departments and agencies participating in the Vulnerabilities Equities 
Process determine that the existing Vulnerabilities Equities Process 
does not sufficiently accommodate the submission and review of 
artificial intelligence security vulnerabilities identified by the 
evaluation required in subsection (b)(1), and that such vulnerabilities 
present public interest considerations meriting review under the 
Vulnerabilities Equities Process, the Federal departments and agencies 
participating in the Vulnerabilities Equities Process shall establish a 
process for the submission and review of such vulnerabilities under the 
Vulnerabilities Equities Process not later than 30 days after the date 
of such determination.
    (d) Report on Vulnerabilities Identified by Artificial Intelligence 
Systems.--Not later than 90 days after the date of the enactment of 
this Act, the Director of National Intelligence shall submit to the 
congressional intelligence committees (as defined in section 3 of the 
National Security Act of 1947 (50 U.S.C. 3003)) a report on--
            (1) the volume of vulnerabilities of information systems 
        identified by artificial intelligence systems;
            (2) the impact of any change in such volume on the 
        functioning of the Vulnerabilities Equities Process; and
            (3) whether the increasingly rapid discovery and 
        exploitation of such vulnerabilities by external cyber actors 
        using artificial intelligence systems materially alters the 
        equity of disclosure.

SEC. 7. SECURITY OF ARTIFICIAL INTELLIGENCE SYSTEMS AND LABORATORIES.

    (a) Definitions.--In this section:
            (1) Center.--The term ``Center'' means the Artificial 
        Intelligence Security Center of the National Security Agency.
            (2) Classified information.--The term ``classified 
        information'' has the meaning given such term in section 805 of 
        the National Security Act of 1947 (50 U.S.C. 3164).
            (3) Cleared industry personnel.--The term ``cleared 
        industry personnel'' means employees or representatives of a 
        covered person who hold an appropriate security clearance and 
        have a demonstrated need to know.
            (4) Congressional intelligence committees.--The term 
        ``congressional intelligence committees'' has the meaning given 
        such term in section 3 of the National Security Act of 1947 (50 
        U.S.C. 3003).
            (5) Covered person.--The term ``covered person'' means a 
        non-Federal person who--
                    (A) is a United States person;
                    (B) develops, deploys, or operates artificial 
                intelligence models or critical enabling 
                infrastructure; and
                    (C) provides the services described in subparagraph 
                (B) to a Federal department or agency.
            (6) Director.--The term ``Director'' means the Director of 
        the National Security Agency.
            (7) Foreign adversary country.--The term ``foreign 
        adversary country'' has the meaning given such term in section 
        2(c) of the Protecting Americans' Data from Foreign Adversaries 
        Act of 2024 (15 U.S.C. 9901(c)).
            (8) Foreign entity of concern.--The term ``foreign entity 
        of concern'' means--
                    (A) a foreign adversary country; or
                    (B) any entity that is controlled or acting under 
                the direction of a foreign adversary country.
            (9) Intelligence.--The term ``intelligence'' has the 
        meaning given such term in section 3 of the National Security 
        Act of 1947 (50 U.S.C. 3003).
            (10) Intelligence community.--The term ``intelligence 
        community'' has the meaning given such term in section 3 of the 
        National Security Act of 1947 (50 U.S.C. 3003).
            (11) Security clearance.--The term ``security clearance'' 
        means an authorization to access classified information.
            (12) Threat information.--The term ``threat information'' 
        means information on--
                    (A) efforts by foreign adversary countries to use 
                products or research of covered persons or other 
                entities or individuals to generate synthetic media for 
                foreign-directed influence campaigns, develop and 
                manage computer network exploitation campaigns, design 
                or develop weapons systems, or enhance surveillance 
                capabilities in ways that undermine the privacy or 
                threaten the security of citizens of the United States;
                    (B) threats posed by foreign entities of concern, 
                including indications of compromise to networks 
                associated with covered persons or other technical 
                indicators, indicating a compromise to the 
                confidentiality, integrity, or availability of an 
                artificial intelligence system, or to the supply chain 
                of an artificial intelligence system, including 
                training or test data, frameworks or software 
                libraries, training or inference computing 
                environments, or other components necessary for the 
                training, management, deployment, or maintenance of an 
                artificial intelligence system;
                    (C) activity of foreign entities of concern to 
                clandestinely, fraudulently, or otherwise maliciously 
                access the systems of covered persons for purposes of 
                illicit technology transfer or otherwise gaining unfair 
                economic advantage, including through techniques to 
                extract a model's technical capabilities to replicate, 
                develop, or improve a foreign artificial intelligence 
                model without authorization by the covered person;
                    (D) activity of foreign entities of concern to 
                sabotage or otherwise clandestinely degrade artificial 
                intelligence systems or the supply chain of an 
                artificial intelligence system, including training or 
                test data, frameworks or software libraries, training 
                or inference computing environments, or other 
                components necessary for the training, management, or 
                maintenance of an artificial intelligence system;
                    (E) observations, emerging concerns, or other 
                inputs from vendors or researchers regarding relevant 
                malicious or clandestine activity of foreign entities 
                of concern toward an artificial intelligence system, 
                its supply chain, or other necessary components;
                    (F) efforts by foreign adversaries or foreign 
                entities to evade detection of malicious activity 
                described in subparagraphs (A), (B), (C) and (D); and
                    (G) any other relevant information the Director of 
                the National Counterintelligence and Security Center 
                and the Assistant Director of the Federal Bureau of 
                Investigation for the Counterintelligence Division deem 
                appropriate.
    (b) Best Practices.--Not later than 90 days after the date of the 
enactment of this Act, the Director of the Cybersecurity and 
Infrastructure Security Agency shall, in collaboration with the 
Director and the Director of the National Institute of Standards and 
Technology and by leveraging efforts of the Information Communications 
Technology Supply Chain Risk Management Task Force to the greatest 
extent practicable, convene a multi-stakeholder process to encourage 
the development and adoption of best practices relating to addressing 
supply chain risks associated with training and maintaining artificial 
intelligence models, which shall ensure consideration of supply chain 
risks associated with--
            (1) activity of foreign entities of concern to 
        clandestinely, fraudulently, or otherwise maliciously access 
        the systems of covered persons for purposes of illicit 
        technology transfer or otherwise gaining unfair economic 
        advantage, including through techniques to extract a model's 
        technical capabilities to replicate, develop, or improve a 
        foreign artificial intelligence model without authorization by 
        the covered person;
            (2) activity of foreign entities of concern to sabotage or 
        otherwise clandestinely degrade artificial intelligence systems 
        or the supply chain of an artificial intelligence system, 
        including training or test data, frameworks or software 
        libraries, training or inference computing environments, or 
        other components necessary for the training, management, or 
        maintenance of an artificial intelligence system; and
            (3) threat information, usage trends, or other input from 
        vendors or researchers regarding observed malicious or 
        clandestine activity of foreign entities of concern toward an 
        artificial intelligence system, its supply chain, or other 
        necessary components.
    (c) Establishment of Pilot Program on Sharing of Intelligence and 
Threat Information With Covered Persons.--
            (1) In general.--Not later than 180 days after the date of 
        the enactment of this Act, the Director shall, in consultation 
        with the Director of the Cybersecurity and Infrastructure 
        Security Agency, establish a pilot program to assess the 
        feasibility and advisability of facilitating the secure sharing 
        with covered persons of intelligence and threat information 
        germane to the securing of the supply chain risks associated 
        with training and maintaining artificial intelligence models 
        procured by the Federal Government.
            (2) Participation.--The Director may not select or exclude 
        covered persons to participate in the pilot program in a manner 
        that provides a competitive advantage or procurement preference 
        to any covered person, to the detriment of another covered 
        person.
            (3) Duration.--The Director shall carry out the pilot 
        program established pursuant to paragraph (1) for not less than 
        a 3-year period beginning on the date of the establishment of 
        the pilot program.
    (d) Participation Requirements.--
            (1) Criteria.--The Director shall establish criteria 
        governing engagement with covered persons under the pilot 
        program required by subsection (c), which may include criteria 
        relating to the following:
                    (A) Relevance to national security.
                    (B) The ability to protect classified or sensitive 
                intelligence information.
                    (C) Cybersecurity and information security 
                maturity.
                    (D) Agreement to comply with intelligence handling, 
                use, and nondisclosure requirements.
                    (E) The availability of cleared personnel of 
                covered persons or willingness of covered persons to 
                increase the number of cleared personnel.
            (2) Nature of participation.--Participation in the pilot 
        program required by subsection (c) shall not be construed as a 
        certification, endorsement, or regulatory approval by the 
        United States Government of any artificial intelligence system 
        or commercial activity and the Director may not exclude a 
        covered person from participating on the basis of political or 
        ideological viewpoints of the covered person or its employees.
    (e) Intelligence Sharing Structure.--
            (1) Authorized modes.--Under the pilot program required by 
        subsection (c), the Director may authorize the sharing of 
        intelligence and threat information as described in paragraph 
        (1) of such subsection through--
                    (A) bilateral exchanges between elements of the 
                intelligence community and a covered person;
                    (B) multilateral exchanges among covered persons, 
                as determined appropriate by the Director; or
                    (C) another designated intelligence-sharing 
                mechanism operated or overseen by the Director.
            (2) Limitation.--Any mechanism established under this 
        section shall be limited to the dissemination of intelligence 
        and threat information and shall not establish standards, 
        requirements, or best practices governing artificial 
        intelligence development or deployment.
    (f) Tailoring, Handling, and Protection of Intelligence.--
            (1) Procedures required.--The Director shall codify 
        procedures to tailor, sanitize, or downgrade the classification 
        level of intelligence shared under the pilot program required 
        by subsection (c) to ensure usability while protecting 
        intelligence sources and methods.
            (2) Examples of procedures.--The procedures developed under 
        paragraph (1) may include the following:
                    (A) The use of tear lines and segregable summaries.
                    (B) The preparation of classified annexes where 
                necessary.
                    (C) Criteria governing the classification level of 
                shared intelligence.
                    (D) The appropriate use of cleared industry 
                personnel.
            (3) Handling requirements.--The Director shall, acting 
        through the Center, codify policies governing the handling, 
        storage, and dissemination of intelligence shared under the 
        pilot program required by subsection (c), including audit and 
        compliance mechanisms.
    (g) Permissible Use and Nondisclosure.--
            (1) Permissible use.--Intelligence shared under the pilot 
        program required by subsection (c) may be used solely for 
        detecting, preventing, or mitigating malicious foreign activity 
        targeting the supply chains associated with training and 
        maintaining artificial intelligence models procured by the 
        Federal Government for intelligence collection, intellectual 
        property theft, and other malicious activities.
            (2) Nondisclosure.--A covered person participating in the 
        pilot program may not disclose any intelligence shared under 
        the pilot program required by subsection (c), except as 
        expressly authorized by the Director acting through the Center.
    (h) Privacy and Civil Liberties.--In planning and coordinating the 
pilot program required by subsection (c), the Director shall, acting 
through the Center, consult with the Civil Liberties Protection Officer 
of the Office of the Director of National Intelligence.
    (i) Evaluation and Reporting.--
            (1) Evaluation.--The Director shall continuously evaluate 
        the effectiveness and risks of the pilot program established 
        under subsection (c).
            (2) Report.--
                    (A) In general.--Not later than 90 days before the 
                date on which the pilot program required by paragraph 
                (1) of subsection (c) terminates pursuant to paragraph 
                (3) of such subsection, the Directors shall submit to 
                the congressional intelligence committees (as defined 
                in section 3 of the National Security Act of 1947 (50 
                U.S.C. 30003)) a report assessing--
                            (i) the effectiveness of intelligence 
                        sharing under the pilot program;
                            (ii) the adequacy of safeguards for 
                        sources, methods, and privacy;
                            (iii) the scope of participation and list 
                        of covered persons participating in the pilot 
                        program; and
                            (iv) whether the program should be 
                        modified, extended, or terminated.
                    (B) Form.--The report submitted pursuant to 
                subparagraph (A) shall be submitted in unclassified 
                form, but may include a classified annex.
    (j) Rule of Construction.--Nothing in this section shall be 
construed--
            (1) to authorize the collection of intelligence on United 
        States persons not authorized by another provision of law;
            (2) to require the disclosure of classified information to 
        unauthorized persons; or
            (3) to establish commercial, competition, or technology 
        policy outside the purview of the intelligence community.
    (k) Exemption From Disclosure; Protection.--Any information shared 
by a covered person or other entity or individual with the United 
States Government pursuant to this section--
            (1) shall be exempt from disclosure and withheld, without 
        discretion, from the public, pursuant to section 552(b)(3)(B) 
        of title 5, United States Code, and any other provision of 
        United States law or law of any State, political subdivision or 
        agency thereof, or Tribe requiring disclosure of information or 
        records; and
            (2) shall not be deemed a waiver of any applicable 
        privilege or protection, including trade secret protection.
    (l) Protection From Liability.--No cause of action shall lie or be 
maintained in any court against any covered person for sharing 
information with the United States Government or another covered person 
pursuant to this section.
                                 <all>